OAK — OnChain Attack Knowledge

Worked example · 2023-06

MOVEit Transfer mass-extortion campaign — Cl0p — 2023-05-27 onward

Loss
more than 2,500 named victim organisations across the campaign; downstream-affected-individual records exceeding 65 million per multi-source aggregate tracking; the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history. Aggregate Cl0p-attributable extortion proceeds across the campaign per [coveware2023moveit], [chainalysis2023clop], and [trmlabs2023moveit] industry-forensic tracking are estimated in the $75M–$100M+ range across the campaign window through year-end 2023, with sustained tail-extortion activity continuing into 2024. Per Coveware aggregate tracking, the median per-victim ransom paid against Cl0p extortion demands was substantially below the original ask, and a majority of named victims chose not to pay (consistent with Cl0p's mid-2023 data-extortion-only operating-model pivot).
OAK Techniques observed
OAK-T5.008 (Ransomware Extortion Payment) — the extortion-payment leg of the ransomware kill chain; OAK-T7.002 (CEX Deposit-Address Layering) — the canonical Cl0p affiliate off-ramp pattern observed across the broader Cl0p-attributable wallet activity per industry-forensic tracking; OAK-T7.001 (Mixer-Routed Hop) — partial / earlier-stage component for portions of the laundering chain consistent with the sector-wide post-Tornado-Cash-designation decline; OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side methodology used by Mandiant FIN11, Microsoft Lace Tempest, Chainalysis, and TRM Labs to maintain Cl0p-affiliate-cluster identification across the multi-victim campaign and across the cluster's 2019-to-2025 operating window.
Attribution
confirmed at the cluster level. CISA / FBI / NSA / U.S. Cyber Command joint cybersecurity advisory AA23-158A "CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability" (June 7, 2023) characterises the campaign and Cl0p TTPs ([cisa2023aa23158aclop]); CISA / FBI joint advisory AA23-039A "#StopRansomware: CLOP Ransomware" (February 8, 2023) characterises the broader Cl0p TTP set ([cisa2023aa23039aclop]); U.S. Treasury OFAC June 2023 designations of multiple Cl0p-affiliated Russian nationals ([ofac2023clopaffiliates]) anchor the named-individual attribution layer. Mandiant FIN11 attribution write-ups and Microsoft Lace Tempest sub-cluster attribution ([mandiantfin11], [microsoftlacetempest]) corroborate the cluster identity. Per-affiliate attribution within the Cl0p cluster for specific victim intrusions is inferred-strong per industry-forensic tracking; per-victim ransom-payment dollar amounts and on-chain payment traces are inferred-strong for most cases (with cluster-aggregate proceeds in the $75M–$100M+ range per [coveware2023moveit], [chainalysis2023clop], [trmlabs2023moveit]) and confirmed-grade only at the cluster level.
OAK-Gnn
OAK-G14 Cl0p / Cl0p. The MOVEit campaign is the canonical worked example of Cl0p's mass-exploitation-of-MFT-products operational pattern and the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history.
Key teaching point
The MOVEit Transfer mass-extortion campaign is the canonical worked example of Cl0p's mass-exploitation-of-MFT-products operational pattern and of the data-extortion-only operating-model novelty that has reshaped the post-2023 ransomware-and-data-extortion ecosystem. The campaign produced the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history (>2,500 named victims, downstream-affected-individual records >65 million) and aggregate Cl0p-attributable extortion proceeds in the $75M–$100M+ range per industry-forensic tracking.

Summary

On May 27, 2023, Cl0p-affiliated operators began mass-exploitation of a previously-undisclosed SQL-injection vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer managed-file-transfer product. The exploitation campaign deployed the LEMURLOOT custom web-shell ("human2.aspx") on compromised MOVEit Transfer instances to enable data-exfiltration without ransomware encryption — the operational model Cl0p had pivoted to in mid-2023 (a data-extortion-only operating model in which encryption is no longer deployed and the negotiation surface is entirely the leaked-data-disclosure threat). The campaign scaled rapidly across MOVEit Transfer customer organisations through June 2023; CISA / FBI / NSA / U.S. Cyber Command issued joint cybersecurity advisory AA23-158A on June 7, 2023 characterising the campaign and Cl0p TTPs.

By year-end 2023 the campaign had named more than 2,500 victim organisations on the Cl0p leak site, with downstream-affected-individual records exceeding 65 million per multi-source aggregate tracking. Named victims included U.S. federal agencies (multiple Department of Energy components, Office of Personnel Management contractors), U.S. state government bodies, U.S. and U.K. private-sector enterprises across multiple sectors (PwC, EY, BBC, British Airways, Boots, U.K. payroll-services firm Zellis as a downstream-cascade source), the New York City Department of Education, the Louisiana Office of Motor Vehicles, and a long tail of cross-sector enterprise IT estates. The campaign produced the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history per HHS, FERC, and SEC sectoral tracking.

Aggregate Cl0p-attributable extortion proceeds across the campaign per industry-forensic tracking are estimated in the $75M–$100M+ range across the campaign window through year-end 2023, with sustained tail-extortion activity continuing into 2024 and into Cl0p's subsequent mass-exploitation campaigns (TeamCity CVE-2023-42793 in late-2023 and Cleo CVE-2024-50623 / CVE-2024-55956 in late-2024). Per Coveware aggregate tracking, a majority of named victims chose not to pay; the median per-victim ransom paid was substantially below the original ask, consistent with Cl0p's data-extortion-only operating-model dynamics.

For OAK's purposes the case is the canonical worked example of mass-exploitation-of-MFT-products operational pattern and of the data-extortion-only operating-model novelty that has reshaped the post-2023 ransomware-and-data-extortion ecosystem. The campaign anchors OAK-G14 at confirmed-grade cluster attribution and at inferred-strong per-flow attribution for individual victim payments.

Timeline (UTC)

When Event OAK ref
2020-12 to 2021-02 Cl0p's first mass-exploitation-of-MFT-products campaign — Accellion FTA exploitation across ~100 customer organisations using CVE-2021-27101 et al; established the cluster's signature operational pattern (precedent campaign)
2023-02 Cl0p's second mass-exploitation-of-MFT-products campaign — GoAnywhere MFT exploitation across ~130 customer organisations using CVE-2023-0669 (precedent campaign)
2023-02-08 CISA / FBI joint cybersecurity advisory AA23-039A "#StopRansomware: CLOP Ransomware" issued ([cisa2023aa23039aclop]) (cluster-attribution document)
2023-05-27 Cl0p-affiliated operators begin mass-exploitation of MOVEit Transfer CVE-2023-34362; LEMURLOOT custom web-shell deployed on compromised instances for data-exfiltration Campaign begins (off-chain entry — out of OAK Tactic scope)
2023-06 OFAC June 2023 designations of multiple Cl0p-affiliated Russian nationals ([ofac2023clopaffiliates]) Named-individual attribution at confirmed
2023-06-07 CISA / FBI / NSA / U.S. Cyber Command joint cybersecurity advisory AA23-158A on MOVEit campaign and Cl0p TTPs ([cisa2023aa23158aclop]) Cluster-attribution at confirmed
2023-06 onward Cl0p leak-site lists rapidly-growing victim cohort; victim-side disclosure tempo cascades through SEC, HHS, FERC, and adjacent sectoral regulator surfaces (sectoral-response coordination)
2023-Q3 onward Per [coveware2023moveit] and [chainalysis2023clop], on-chain ransom-payment volume tracking against Cl0p-affiliate-controlled wallets shows aggregate proceeds in the $75M–$100M+ range; majority of named victims do not pay T7.002 downstream observed across cluster wallet activity
2023-12 Year-end aggregate: >2,500 named victims; downstream-affected-individual records >65 million; largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history (campaign aggregate metrics)
2024 onward Sustained tail-extortion activity; Cl0p subsequent mass-exploitation campaigns (TeamCity, Cleo) extend the cluster's operational pattern (continued operating tempo)

What defenders observed

  • Mass-exploitation-of-MFT-products as Cl0p's signature operational pattern. The MOVEit campaign extended Cl0p's signature mass-exploitation-of-MFT-products operational pattern from the 2020-2021 Accellion FTA campaign and the early-2023 GoAnywhere MFT campaign. Defender control-set design for MFT-product zero-day disclosure should treat Cl0p-attributable mass-exploitation as the default expectation, not as an exception. The cluster's 2024 Cleo campaign continued the pattern, demonstrating sustained operational tempo.
  • Data-extortion-only operating-model novelty. Cl0p's mid-2023 pivot to data-extortion-only — encryption is no longer deployed and the negotiation surface is entirely the leaked-data-disclosure threat — is the canonical worked case in the public record for encryption-less ransomware-cluster operating model. Successor and adjacent clusters (Karakurt, BianLian, RansomHouse) have adopted variants of the data-extortion-only pattern. Defender control-set design for ransomware response now needs to assume that encryption-deployment is not the only operating model and data-disclosure-threat-only-extortion is part of the threat-actor toolkit.
  • Per-victim payment-decision cascade and non-payment majority. Per Coveware aggregate tracking, a majority of named victims chose not to pay; the median per-victim ransom paid was substantially below the original ask. The aggregate-level non-payment pattern is consistent with Cl0p's data-extortion-only dynamics — without encryption, the negotiation surface is weaker against organisations whose data-archive content is not uniquely high-value or uniquely-disclosure-sensitive. Defender / CISO decision-making literature should treat aggregate non-payment as a structural feature of the data-extortion-only model.
  • Sectoral-disclosure-cohort cascade. The MOVEit campaign produced the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history. Sectoral regulators (SEC, HHS, FERC, FBI / CISA) coordinated cross-sector incident-disclosure tempo. Future MFT-class mass-exploitation campaigns should be expected to produce comparable sectoral-disclosure-cohort cascades.

What this example tells contributors writing future Technique pages

  • Mass-exploitation campaigns produce aggregate-level on-chain attribution at confirmed-grade cluster level and inferred-strong per-flow attribution at individual-victim-payment level. Future mass-exploitation-attributable examples should expect this asymmetry. The MOVEit campaign is the canonical worked example.
  • Data-extortion-only operating-model is a sustained threat-actor toolkit feature. Future ransomware-cluster attribution examples should mark whether the cluster operates in encryption-and-data-extortion (double-extortion) mode or in data-extortion-only mode; the operating-model layer materially affects defender control-set design and victim-decision dynamics.
  • Industry-forensic-provider aggregate tracking is the load-bearing on-chain attribution layer for mass-extortion campaigns. Coveware / Chainalysis / TRM Labs aggregate tracking is the load-bearing on-chain attribution surface for the MOVEit campaign in the public record. Future contributors writing mass-exploitation-attribution examples should anchor on industry-forensic-provider aggregate tracking citations explicitly.

Public references

  • [cisa2023aa23158aclop] — Joint CISA / FBI / NSA / U.S. Cyber Command cybersecurity advisory AA23-158A on Cl0p MOVEit campaign, June 7, 2023.
  • [cisa2023aa23039aclop] — Joint CISA / FBI cybersecurity advisory AA23-039A "#StopRansomware: CLOP Ransomware," February 8, 2023.
  • [ofac2023clopaffiliates] — U.S. Department of the Treasury OFAC June 2023 designations of multiple Cl0p-affiliated Russian nationals.
  • [ukrcyberpolice2021clop] — Ukrainian Cyber Police announcement of June 2021 arrests of multiple Cl0p-affiliated individuals in coordination with U.S. and South Korean law enforcement.
  • [mandiantfin11] — Mandiant FIN11 / TA505 / Cl0p tracker write-up on operator-cohort attribution.
  • [microsoftlacetempest] — Microsoft Threat Intelligence on Lace Tempest Cl0p-affiliated MOVEit-campaign-running sub-cluster.
  • [coveware2023moveit] — Coveware retrospective on the MOVEit campaign victim-cohort and ransom-payment aggregates.
  • [chainalysis2023clop] — Chainalysis forensic write-up of Cl0p downstream-laundering profile and MOVEit-campaign on-chain payment tracing.
  • [trmlabs2023moveit] — TRM Labs forensic write-up of MOVEit-campaign Bitcoin payment tracing.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report; documents Cl0p aggregate proceeds and the data-extortion-only pivot.

Discussion

The MOVEit Transfer mass-extortion campaign is the canonical worked example of Cl0p's mass-exploitation-of-MFT-products operational pattern and of the data-extortion-only operating-model novelty that has reshaped the post-2023 ransomware-and-data-extortion ecosystem. The campaign produced the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history (>2,500 named victims, downstream-affected-individual records >65 million) and aggregate Cl0p-attributable extortion proceeds in the $75M–$100M+ range per industry-forensic tracking.

The case anchors OAK-G14 at confirmed-grade cluster attribution and at inferred-strong per-flow attribution for individual victim payments. The cluster-vs-per-flow attribution-strength asymmetry is the structural OAK observation: confirmed-grade cluster attribution rests on the multi-jurisdiction CISA / FBI / NSA / OFAC architecture and the named-individual OFAC June 2023 designations; per-flow inferred-strong attribution rests on industry-forensic-provider aggregate tracking and per-victim disclosure tempo that varies materially across the >2,500-victim cohort.

The data-extortion-only operating-model novelty is a structural feature of the post-2023 ransomware-and-data-extortion ecosystem. Defender control-set design now needs to assume that encryption-deployment is not the only operating-model and that data-disclosure-threat-only-extortion is part of the threat-actor toolkit. Future ransomware-cluster attribution examples should mark whether the cluster operates in double-extortion or data-extortion-only mode; the distinction affects defender control-set design, victim-decision dynamics, and the on-chain payment-trace public-record surface.

Techniques demonstrated (4)